dicted dicted / Legal

Subprocessor List

Effective date: 2026-04-19 Last updated: 2026-06-11

Every change to this list (added, removed, or replaced subprocessors) is recorded in the public Subprocessor Change Log so the 30-day notice commitment below can be audited against an actual paper trail.

This page lists every third-party service (subprocessor) that dicted shares your data with in order to deliver the service. We deliberately keep this list small and limit AI processing to well-known, established providers with strong privacy reputations — predominantly US-based. We do not route your content to unknown, low-profile, or jurisdictionally unclear providers.

We will notify you by email of any new subprocessor at least 30 days before they gain access to your data, giving you time to object. If you object, you may cancel your subscription and receive a pro-rata refund of any pre-paid unused portion.

We may add or change subprocessors over time. Material changes to our subprocessor list will be notified to users at least 30 days before taking effect where practicable, via email and a prominent notice at this page.

For full context on how we handle your data and your rights, see our Privacy Policy.

AI processing subprocessors

These providers apply machine-learning models to your content (transcribe audio, summarise transcripts, etc.) on the paths described below. For dictation, the primary transcription path runs on infrastructure operated directly by Dicted (Oracle Cloud + Dicted-operated GPU compute) and is not listed here. Cloud AI subprocessors apply only to fallback paths and to meeting / artifact processing.

Subprocessor Purpose Data shared Location
OpenAI Speech-to-text fallback for dictation when the primary path is at capacity or unavailable Audio (discarded after transcription) United States
Soniox Speech-to-text + diarization fallback for meetings Audio (discarded after transcription) United States
Deepgram Speech-to-text fallback for dictation and meetings when the primary path is at capacity or unavailable Audio (discarded after transcription) United States
AssemblyAI Speech-to-text + diarization fallback for meetings when the primary path is at capacity or unavailable Audio (discarded after transcription) United States
Gladia Speech-to-text fallback for dictation and meetings when the primary path is at capacity or unavailable Audio (discarded after transcription) European Union (France)
Groq Speech-to-text fallback (dictation and meetings) and cloud language-model inference fallback for transcript processing — meeting summaries, minutes, action items, smart actions, Smart Polish, Voice Edit — when the primary path is at capacity or unavailable Audio for speech-to-text; transcript text (never audio) for language-model inference United States
Google (Gemini Flash) Cloud language-model fallback when the primary self-hosted path is at capacity or unavailable — for meeting summaries, minutes, action items, smart actions, Smart Polish, Voice Edit. Receives transcript text only when invoked. Never receives audio. Transcripts (never audio) United States

The primary language-model path runs on infrastructure operated directly by Dicted (Oracle Cloud + Dicted-operated GPU compute, self-hosted Gemma 4-26B-A4B) and is not listed in the subprocessor table above — transcript text never leaves Dicted's network on that path.

We have selected each AI subprocessor above on the basis of their published API terms, which commit them to:

  • Not retain your content after the response returns (or only for the minimum necessary to deliver the response, typically under an explicit "zero-retention" API mode which we enable where the provider offers it)
  • Not use your content to train speech or language models
  • Not disclose your content to third parties except as required to deliver the service

These commitments live in the public API Terms of Service we accept when we integrate each provider. We do not currently hold separately negotiated custom Data Processing Agreements with any AI subprocessor — if that changes we will update this list.

Infrastructure subprocessors

These providers carry, store, or compute on your data without applying AI models of their own.

Subprocessor Purpose Data shared Location
Cloudflare R2 Meeting file storage Meeting audio files (encrypted at rest) United States / global edge
RunPod (Secure Cloud) GPU compute for Dicted's self-hosted meeting transcription + diarization pipeline. RunPod executes our Docker image; they do not provide an AI model of their own. Secure Cloud tier only — Community Cloud is not used. Meeting audio (transient — discarded after transcription) Pinned region (United States)
Stripe Payment processing Name, email, card token United States / Ireland
Oracle Cloud Infrastructure Application hosting + Dicted-operated GPU compute for the primary dictation transcription path All operational data, dictation audio (transient) United States
Amazon Web Services (SES) Transactional and opt-in marketing email delivery Email address + message United States
Sentry Crash + error reporting Technical stack traces (content redacted where feasible) United States

Cross-border disclosure mechanisms

All of our AI and infrastructure subprocessors are US-based or pinned to a US region, with the single exception of Gladia — a speech-to-text fallback provider established in the European Union (France). Your personal information is disclosed internationally to deliver the service.

Provider Mechanism
OpenAI Published API terms with zero-retention mode enabled + SOC 2 Type II
Soniox Published API terms (no-retention, no-training) + SOC 2 Type II
Deepgram Published API terms (no-retention, no-training)
AssemblyAI Published API terms (no-retention, no-training)
Gladia Published API terms (no-retention, no-training)
Groq Published API terms (no-retention, no-training)
Google (Gemini) Enterprise terms for zero-retention and no-training
Cloudflare R2 Published terms of service + SOC 2 / ISO 27001
RunPod (Secure Cloud) Published terms of service + SOC 2 Type II (Secure Cloud tier — Community Cloud is not used)
Stripe PCI-DSS Level 1 + SOC 2 + published terms of service
Oracle Cloud SOC 2 Type II + published terms of service
AWS (SES) SOC 2 + published terms of service
Sentry Published terms of service + content-scrubbing filter we configure

We do not currently hold separately negotiated custom Data Processing Agreements with these providers — our posture is the default commercial API relationship under each provider's published terms. Where a provider offers a zero-retention API mode as a per-request flag or account setting, we use it.

Note: dicted is not offered in the EEA or UK, so EU-US Data Privacy Framework (DPF) certification and UK International Data Transfer Agreements (IDTA) are not relied on. When we expand to those regions, this page will be updated with the applicable DPF / SCC / IDTA mechanisms and users notified in advance.

Change notification

We aim to select subprocessors from established, well-known providers — predominantly US-based — with published privacy policies and recognised independent security attestations (SOC 2 Type II, ISO 27001, or comparable) where available. We do not add obscure or low-reputation providers even if they are cheaper.

Every addition, removal, or replacement is logged. Changes to this list are recorded in the Subprocessor Change Log, which is append-only and dated. The change log documents the date of email notice for each new subprocessor, the 30-day objection window, and the date the new subprocessor began receiving data. The change log is the canonical evidence trail for the 30-day notice commitment above.

Contact [email protected] with any questions about this list.

Other legal documents

Terms of Service Privacy Policy Fair Use & Anti-Abuse Policy Cookie Policy Refund & Cancellation Policy Acceptable Use Policy Takedown Procedure Data Processing Agreement Subprocessor Change Log Open-Source & Model Attributions

© 2026 M37 Tech Pty Ltd. All rights reserved. · ABN 88 696 420 363